Re: Security log file needing save

From: A. Tolga KILINĒ (kilinc@tis.havelsan.com.tr)
Date: 11/28/02


From: "A. Tolga KILINĒ" <kilinc@tis.havelsan.com.tr>
Date: Thu, 28 Nov 2002 13:53:51 +0200

Hi Toni,
We also need a similar consolidation requirement. Can you send me an example
script that you wrote?
Regards,
Tolga

"Toni Lassila" <mpao@mc-europe.com> wrote in message
news:b11796dd.0211270255.7d9ca4f1@posting.google.com...
> "Brian Roberson" <brian@nospam.txt> wrote in message
news:<uWA4q$YlCHA.1960@tkmsftngp04>...
> > Is there a way to configure the DC's to save the log files once they
fill up
> > and start a new log file? We really need to save the log files and
right
> > now they are just overwriting themselves as needed. The problem with
this
> > strategy is that one rogue process can overwrite much of the history in
the
> > logs. Our security log file is getting overwritten all of the time by
one
> > particular process that is out of control. We lose all history!
>
> Use dumpel.exe or some other log-dumping tool to write the logs to disk
> and clear the log regularly (with task scheduler):
>
>
<http://www.microsoft.com/windows2000/techinfo/reskit/tools/existing/dumpel-
o.asp>
>
> I even went as far as to write a script that pulls these from all servers
> and imports the logs into SQL Server. It's not Unix style real-time
> syslogging, but it's still better than nothing.



Relevant Pages

  • Re: Recording AD Logons to SQL Database
    ... and from what pc by running the code below in my login script. ... ' Specify SQL Server, Instance name, and database. ... on demand to combine them into a single csv file. ... intervention is required in order to keep the log files to a reasonable size ...
    (microsoft.public.windows.server.scripting)
  • Re: [Info-Ingres] Setting up Ingres Security Auditing for query_text
    ... of a shell script to archive the audit files, ... refusing to restart if there is a problem in the log files. ... Register into a normal database, ... Set the audit files to be small to test file "switching". ...
    (comp.databases.ingres)
  • Re: VBScript cant read NTBackup log files
    ... Even though the log files appear to be text files, my script returns the same three garbage characters from every NTBackup log file. ...
    (microsoft.public.windows.server.scripting)
  • Re: Size of wtmp files
    ... for logrotate to configure it the way you want. ... > a script to run 'last' repeatedly on zcatted versions of the rotated files, ... an attacker has full reign to edit the log files with impunity. ...
    (comp.os.linux.misc)
  • REQ: Raw log file generator script
    ... I mean that I want to create log files that will contain ALL POSSIBLE ... spend, entry and exit page, browser type and version, operating system, ... Unless somebody can send me a better script to create log files. ... that does not give me the raw log data. ...
    (alt.php)